rancher / os

Tiny Linux distro that runs the entire OS as Docker containers
https://rancher.com/docs/os/v1.x/en/
Apache License 2.0
6.44k stars 657 forks source link

CVE-2021-3156 #3043

Open mikemoate opened 3 years ago

mikemoate commented 3 years ago

RancherOS Version: (ros os version) 1.5.7 Where are you running RancherOS? (docker-machine, AWS, GCE, baremetal, etc.) AWS

There is a new vulnerability in sudo that impacts Rancher OS.

@dweomer @niusmallnan @Jason-ZW will Rancher OS be updated to fix this security issue, or is it truly now EoL?

olljanat commented 3 years ago

@mikemoate I just wonder that how you think that this one would be issue on RancherOS? Documentation quite clearly says that it is not supported to add users ( https://rancher.com/docs/os/v1.x/en/configuration/users/ ) and rancher user have anyway sudo rights.